GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,464
Erlang
33
GitHub Actions
22
Go
2,163
Maven
5,000+
npm
3,821
NuGet
696
pip
3,502
Pub
12
RubyGems
909
Rust
904
Swift
38
Unreviewed advisories
All unreviewed
5,000+
563 advisories
Filter by severity
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded Erlang cookie for ejabberd replication.
Moderate
Unreviewed
CVE-2020-15325
was published
Sep 30, 2022
IBM Java Security Components in IBM SDK, Java Technology Edition 8 before SR1 FP10, 7 R1 before...
Moderate
Unreviewed
CVE-2015-1931
was published
Sep 30, 2022
Dell GeoDrive, Versions 2.1 - 2.2, contains an information disclosure vulnerability. An...
Moderate
Unreviewed
CVE-2022-33918
was published
Oct 13, 2022
An issue has been discovered in hunter2 affecting all versions before 2.1.0. Improper handling of...
Moderate
Unreviewed
CVE-2022-3540
was published
Oct 17, 2022
A flaw was found in ovirt-engine, which leads to the logging of plaintext passwords in the log...
Moderate
Unreviewed
CVE-2022-2805
was published
Oct 19, 2022
"IBM Business Automation Workflow 18.0.0.0, 18.0.0.1, 18.0.0.2, 19.0.0.1, 19.0.0.2, 19.0.0.3, 20...
Moderate
Unreviewed
CVE-2022-35279
was published
Nov 4, 2022
"IBM Cognos Analytics 11.2.1, 11.2.0, 11.1.7 stores user credentials in plain clear text which...
Moderate
Unreviewed
CVE-2022-34339
was published
Nov 4, 2022
"IBM Security Guardium 10.5, 10.6, 11.0, 11.1, 11.2, 11.3, and 11.4 stores user credentials in...
Moderate
Unreviewed
CVE-2021-39077
was published
Nov 4, 2022
"IBM Robotic Process Automation 21.0.1 and 21.0.2 could disclose sensitive version information...
Moderate
Unreviewed
CVE-2022-38710
was published
Nov 4, 2022
The PassWork extension 5.0.9 for Chrome and other browsers allows an attacker to obtain the...
High
Unreviewed
CVE-2022-42956
was published
Nov 7, 2022
The PassWork extension 5.0.9 for Chrome and other browsers allows an attacker to obtain cleartext...
High
Unreviewed
CVE-2022-42955
was published
Nov 7, 2022
A vulnerability has been identified in QMS Automotive (All versions). User credentials are stored...
Critical
Unreviewed
CVE-2022-43958
was published
Nov 8, 2022
Plaintext storage of password after a reset in org.xwiki.platform:xwiki-platform-security-authentication-default
Moderate
CVE-2022-41933
was published
for
org.xwiki.platform:xwiki-platform-security-authentication-default
(Maven)
Nov 21, 2022
Password exposure in H2 Database
High
CVE-2022-45868
was published
for
com.h2database:h2
(Maven)
Nov 23, 2022
Cleartext Storage of Sensitive Information in Memory vulnerability in Mitsubishi Electric...
Moderate
Unreviewed
CVE-2022-29832
was published
Nov 25, 2022
Cleartext Storage of Sensitive Information vulnerability in Mitsubishi Electric GX Works3 all...
High
Unreviewed
CVE-2022-25164
was published
Nov 25, 2022
Cleartext Storage of Sensitive Information vulnerability in Mitsubishi Electric GX Works3...
High
Unreviewed
CVE-2022-29826
was published
Nov 25, 2022
The /device/signin end-point for the Ourphoto App version 1.4.1 discloses clear-text password...
High
Unreviewed
CVE-2022-24188
was published
Nov 29, 2022
IXPdata EasyInstall 6.6.14725 contains an access control issue.
High
Unreviewed
CVE-2022-35120
was published
Dec 2, 2022
A cleartext storage of sensitive information vulnerability exists in PcVue versions 8.10 through...
Moderate
Unreviewed
CVE-2022-4312
was published
Dec 12, 2022
The vCenter Server contains an information disclosure vulnerability due to the logging of...
Moderate
Unreviewed
CVE-2022-31697
was published
Dec 13, 2022
Sensitive information was stored in plain text in a file that is accessible by a user with a...
Moderate
Unreviewed
CVE-2022-47512
was published
Dec 19, 2022
IBM Security Verify Governance, Identity Manager 10.0.1 stores sensitive information including...
Moderate
Unreviewed
CVE-2022-22457
was published
Dec 23, 2022
Certain General Electric Renewable Energy products store cleartext credentials in flash memory....
Moderate
Unreviewed
CVE-2022-24120
was published
Dec 26, 2022
An issue was discovered in WeCube Platform 3.2.2. Cleartext passwords are displayed in the...
High
Unreviewed
CVE-2022-37785
was published
Jan 1, 2023
ProTip!
Advisories are also available from the
GraphQL API